The problem is there is no real way to separate "data" and "instructions" in LLMs like there is for SQL